mscbcp32.exe - Anybody Seen It?

  • Thread starter Thread starter Samuel M. Clothman
  • Start date Start date
S

Samuel M. Clothman

I just came back from a client computer that had triggered a number of
security alerts on my network. I looked in the registry and found

IEXPLORERD = mscbcp32.exe in the
HKLM\Software\Microsoft\CurrentVersion\Run key.

It also edited the hosts file to route access to various anti-virus
sites back to 127.0.0.1


Symantec Anti-virus and McAfee and TrendMicro all failed to identify
the file as a virus, but removing the file solved the problem. Has
anybody out there seen this? Does anybody know what it is?
 
Looks like it's a variant of GAOBOT. I submitted the sample to all
known anti-virus providers.
 
Back
Top